Skip to content

gmh5225/AntiKernelDebug-POC

Repository files navigation

AntiKernelDebug-poc

What's this?

A POC about how to detect windows kernel debug by pool tag.

How does this poc actually work?

Query system pool tag information matches TagUlong == 'oIdK'.

Tested in Win10 1809

image

Compile

  • Visual Studio 2019
  • llvm-msvc [link]

About

POC about how to detect windows kernel debug by pool tag.

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published